Legal

Privacy Policy

What we collect, what we refuse to collect, and exactly how to get rid of all of it.

Effective
12 September 2026
Applies to
All Figo apps and figoapp.net

The short version

In one paragraph

Your financial data is yours. We do not sell it, we do not use it for advertising, and we never connect to your bank. Gmail scanning is opt-in and reads sender addresses and subject lines only — never message bodies. AI features send figures, never your identity. You can delete your account and everything attached to it from inside the app, at any time.

The rest of this page is the long version. It is written to be read, not to be survived.

Who we are

Figo is a software studio operated by Varun Anand, an individual developer based in India. Figo publishes Recurrs and is building Neuron.

This policy governs the Figo apps, this website, and any related services. Using them means you accept it. Where a specific app does something different, that difference is called out by name below.

What we collect

Information you give us

DataWhenWhere it lives
Name and email addressWhen you create an accountSupabase, encrypted at rest
Subscriptions, expenses, income, trials, loansWhen you add themOn device, and in Supabase for sync
Payment methods and balancesWhen you add themOn device and Supabase — names and balances only, never card numbers
Receipts and attachmentsWhen you scan or uploadSupabase storage
Profiles and connectionsWhen you create or accept themSupabase
Support messages and feedbackWhen you send themSupabase

Information collected automatically

  • Device and OS version — for compatibility and crash diagnostics.
  • Push token — stored only so renewal notifications can be delivered. Never used for tracking.
  • App version — sent with API requests so the server knows what it is talking to.
  • Exchange rates — fetched from a public rates API. No personal data is sent with that request.

What we never collect

  • Card numbers, CVVs, or bank account details.
  • Bank logins or real transaction feeds. Figo apps do not connect to your bank at all.
  • Background location. Location automations run against a radius you set, evaluated on your device.
  • Your contact list or calendar.
  • Photos, beyond the specific images you choose to attach.
  • Email message bodies. See Gmail scanning.
  • Browsing history, or data from any other app on your device.

How we use it

Strictly to run the service. There is no advertising business here to feed.

PurposeData usedBasis
Running the tracking featuresYour entriesContract
Sync across your devicesYour entries, account IDContract
Renewal remindersDates, push tokenContract
AI insights and autofillNames, amounts, categoriesConsent — opt-in
Gmail subscription detectionSender and subject linesConsent — opt-in
Verifying a paid subscriptionAccount ID, store receiptContract
Preventing abuse of AI quotasAccount ID, usage countsLegitimate interest

Gmail scanning

Entirely optional

Nothing happens until you complete Google’s OAuth flow yourself. You can disconnect from inside the app, or revoke access at myaccount.google.com/permissions, at any moment.

What is read

  • Sender addresses and subject lines only. Message bodies are never downloaded or read.
  • The query is filtered to billing language — receipt, invoice, subscription — to keep the scope narrow.
  • Only the last six months of mail is considered.

What is stored

  • A Google refresh token, held server-side in Supabase, encrypted at rest and fenced by row-level security. It never reaches your device and is never returned in an API response.
  • The derived result only — for example “Spotify, ₹119 monthly”. The email addresses and subjects that produced it are not stored anywhere.

Google’s rules

Our use of data from Gmail follows the Google API Services User Data Policy, including its Limited Use requirements. Gmail data is never used for advertising, never sold or passed to a third party for their own use, and never used to train any AI model.

Disconnecting deletes the refresh token immediately and clears cached suggestions. Subscriptions you already added stay — removing them is your call.

AI features

AI autofill and the AI analyser run through our own backend, which calls Google’s Gemini API. The request carries the figures it needs and nothing that identifies you.

  • Sent: subscription and expense names, amounts, billing cycles, categories, and aggregate totals.
  • Never sent: your name, email, account ID, device details, or anything from your inbox.

Not financial advice

AI output is informational. It is generated from your own numbers and can be wrong. Check anything before acting on it.

Storage and security

On your device

Entries are stored locally so the app works offline, using each platform’s native store.

In the cloud

Sync and accounts run on Supabase, a managed PostgreSQL platform hosted on AWS. Everything there is:

  • encrypted in transit over TLS 1.2 or higher;
  • encrypted at rest with AES-256;
  • fenced by row-level security — database-level policies that make one account’s rows unreadable to another, even if the application layer were compromised.

Keys

The public key embedded in our apps and in this website is designed to be public. It grants nothing on its own: every read and write is still checked against row-level security, and personal data requires a valid signed-in session.

What we cannot promise

No transmission or storage method is perfectly secure. We use current industry practice, but we cannot guarantee absolute security. If a breach ever affects your personal data, we will tell affected users as the law requires.

Third parties

ServicePurposeWhat it sees
SupabaseDatabase, auth, storage, edge functionsAccount details and your entries
Google GeminiAI autofill and analysisFigures and category names, no identity
Google OAuth / GmailOptional billing-email detectionSender addresses and subjects, processed and discarded
AppleApp Store payments, push deliveryPayment data — Apple only, never us
Google PlayAndroid paymentsPayment data — Google only, never us
Public rates APICurrency conversionNothing personal

There are no advertising networks, tracking SDKs or analytics frameworks inside the apps.

Data sharing

We do not sell your data

Not to advertisers, not to data brokers, not to anyone. There is no version of this where your spending becomes someone else’s product.

Information is disclosed only in these cases:

  • Service providers listed above, for the stated purpose and nothing else.
  • Legal compliance, where a valid order under applicable law requires it.
  • Protection of rights, where disclosure is necessary to prevent harm.
  • Business transfer, if Figo is ever acquired — with notice to you before any transfer.
  • Your explicit consent, for anything else.

Sharing you initiate — splits, connections, shared profiles — shows the other person only the items you shared with them, and they can leave at any time.

Sign-in and passwords

  • Email and password — hashed with bcrypt by Supabase Auth before storage. We never see or store a plaintext password.
  • Sign in with Apple — we receive a name and an email or relay address. Never your Apple ID password.
  • Sign in with Google — we receive a name and email address. Never your Google password.

Sessions use short-lived JSON Web Tokens held in the app’s sandboxed storage, and all auth traffic is HTTPS.

Payments

Every purchase is processed by Apple or Google as merchant of record. We never receive, process or store card numbers or bank details. What reaches us is a receipt confirming whether a paid subscription is currently active — nothing more.

Retention and deletion

  • While your account is active, we keep your data so the apps work.
  • On account deletion, everything personal is permanently removed from our database within 30 days. Deleting the app removes the on-device copy immediately.
  • Gmail refresh tokens are deleted the moment you disconnect, or on account deletion.
  • Push tokens are deleted on account deletion or when you revoke notifications.
  • Disaster-recovery backups roll off within seven days and are not individually restorable.
  • Free-tier receipts are purged after seven days by design; receipts captured while subscribed are kept.

Delete your account from inside the app under Settings, or ask us and we will do it.

Your rights

RightWhat it meansHow
AccessA copy of what we hold about youAsk us
RectificationCorrect anything wrongEdit in the app
ErasureDelete the account and everything with itSettings → Account → Delete
PortabilityMachine-readable exportExport to CSV / Excel
RestrictionLimit how we process your dataAsk us
ObjectionObject to legitimate-interest processingAsk us
Withdraw consentTurn off Gmail scanning or AIApp settings, any time

We answer verifiable requests within 30 days. If you are in the EEA, UK or California you have additional rights under GDPR, UK GDPR or CCPA — we apply them to everyone regardless of where you live.

Children

Figo apps are not directed at children under 13, or under 16 in the EEA, and we do not knowingly collect their data. If you believe a child has given us personal information, tell us and we will delete it promptly.

International users

Figo operates from India; our infrastructure runs in the United States. Using the service means your data may be transferred to and processed in both. For EEA and UK users we rely on consent for optional features and on contract performance for the rest, and our infrastructure provider operates under the EU-US Data Privacy Framework.

This website

figoapp.net sets no advertising or tracking cookies and runs no third-party analytics. The forms on the feedback, contact and testers pages submit directly to our own database and store only what you typed, plus your browser’s user-agent string, which helps us reproduce bugs.

Changes

We update this policy when practice, technology or law changes. Material changes get a notice in-app and a new effective date at the top of this page. Continuing to use the apps after that means you accept the revision.

Contact

Privacy questions go to figo.productive@gmail.com, or through the contact form. Read the Terms of Service alongside this policy — they work together.